Getting Data In

WinEventLogChannel - saveCheckpointStr : Unable to write checkpoint with a null string

dmlee
Communicator

Hi, there are lots of ERROR messages in splunkd.log (version 4.2.3 , play as LightForwarder)

and this Splunk LWF send all of the WinEventLog to indexer again and again , so there are many duplicate events in indexer.

09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Unable to write checkpoint with a null string
09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - WELCheckPoint::save: Failed to save checkpoint file='': 操作順利完成(success)。
09-20-2011 12:15:49.837 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Failed to rename checkpoint file '.tmp' -> '': 系統找不到指定的路徑(can't find the path)


any idea about it? thanks

Tags (1)
1 Solution

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

View solution in original post

0 Karma

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

0 Karma

jumper4000
Explorer

I'm having the same issue. Any help would be appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...